I have a SRX 240 Cluster that cannot be polled via SNMP but it responds to SSH i have SNMP allowed under Interface and its vlans and also under routing instance. I checked the traffic logs and from what i can see is the policy that allows SSH also allows SNMP and SNMP is traffic is hitting the same policy but no response is received for SNMP.
Session ID: 71710, Policy name: From_HOandRV/22, State: Active, Timeout: 1800, Valid
In: 10.1.0.62/57327 --> 10.1.32.1/22;tcp, If: reth0.34, Pkts: 7, Bytes: 1472
Out: 10.1.32.1/22 --> 10.1.0.62/57327;tcp, If: .local..4, Pkts: 7, Bytes: 2169
Session ID: 39397, Policy name: From_HOandRV/22, State: Active, Timeout: 8, Valid
In: 10.1.0.62/57654 --> 10.1.32.1/161;udp, If: reth0.34, Pkts: 1, Bytes: 67
Out: 10.1.32.1/161 --> 10.1.0.62/57654;udp, If: .local..4, Pkts: 0, Bytes: 0
Yes SNMP is allowed on all the interfaces traffic enters and leaves, i have enabled SNMP traceoptions and here's what i see
snmpd[5093] >>> Get-Bulk-Request
snmpd[5093] >>> Source: 10.1.0.62
snmpd[5093] >>> Destination: 10.1.32.1
snmpd[5093] >>> Version: SNMPv2
snmpd[5093] >>> Request_id: 0x5093
snmpd[5093] >>> Community: abcxvzxd ----- the correct SNMP V2 String from the SNMP server
snmpd[5093] >>> Non-repeaters: 0
snmpd[5093] >>> Max-repetitions: 20
snmpd[5093] >>> OID : std
snmpd[5093] >>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
snmpd[5093] >>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
snmpd[5093] >>> Get-Bulk-Request
snmpd[5093] >>> Source: 10.1.0.62
snmpd[5093] >>> Destination: 10.1.32.1
snmpd[5093] >>> Version: SNMPv2
snmpd[5093] >>> Request_id: 0x5093
snmpd[5093] >>> Community: zxd ------- it removd part of the snmp string and only took the last few characters
snmpd[5093] >>> Non-repeaters: 0
snmpd[5093] >>> Max-repetitions: 20
snmpd[5093] >>> OID : std
snmpd[5093] >>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
SNMPD_AUTH_FAILURE: nsa_log_community: unauthorized SNMP community from 10.1.0.62 to 10.1.32.1 ( abcxvzxd) --- then SRX classifies the entire string as unauthorized community string. Any help to resolve this issue would be appritiated.